← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 1714728] Re: [CVEs] Creates executables class files with wrong permissions, Unsafe deserialization leads to code execution

 

This bug was fixed in the package jython - 2.5.3-1ubuntu0.1

---------------
jython (2.5.3-1ubuntu0.1) trusty-security; urgency=high

  [ Simon Quigley ]
  * SECURITY UPDATE: Creates executables class files with wrong permissions
    (LP: #1714728)
    - CVE-2013-2027
    - 1-CVE-2013-2027.patch
    - 2-CVE-2013-2027.patch
    - 3-CVE-2013-2027.patch
    - Thanks to Lubomir Rintel for the patches!

  [ Markus Koschany ]
  * SECURITY UPDATE: Unsafe deserialization may lead to arbitrary code
    execution
    - CVE-2016-4000
    - CVE-2016-4000.patch

 -- Simon Quigley <tsimonq2@xxxxxxxxxx>  Wed, 20 Sep 2017 21:10:50 -0500

** Changed in: jython (Ubuntu Trusty)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/1714728

Title:
  [CVEs] Creates executables class files with wrong permissions, Unsafe
  deserialization leads to code execution

Status in jython package in Ubuntu:
  Fix Released
Status in jython source package in Trusty:
  Fix Released
Status in jython source package in Xenial:
  Fix Released
Status in jython source package in Zesty:
  Fix Released
Status in jython source package in Artful:
  Fix Released

Bug description:
  This aims to fix two CVEs:

   - CVE-2013-2027: Creates executables class files with wrong permissions
   - CVE-2016-4000: Unsafe deserialization leads to code execution

  While CVE-2013-2027 is not shown as fixed in Debian and Red Hat, it is
  fixed in OpenSUSE (openSUSE-SU-2015:0269-1), we can backport their
  patches.

  CVE-2016-4000 was fixed in Debian in 2.5.3-17, and that's in Artful,
  but we still need fixes for Trusty, Xenial, and Zesty.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jython/+bug/1714728/+subscriptions


References